Ransomware Response
Severity: Critical
Contain, preserve evidence, and activate recovery workflows.
- Isolate infected systems from the network.
- Preserve volatile evidence and backup logs.
- Validate restore points and check backups.
- Notify stakeholders and law enforcement.